SAA-C03 Design Secure Architectures Practice Question
A healthcare company stores protected health information in an Amazon S3 bucket. Auditors require that every object be encrypted with a customer managed AWS KMS key, that key rotation be controlled by the company, and that the company be able to revoke access to the data immediately by disabling the key. Which encryption configuration meets these requirements?
⚠ Common exam trap
The trap here is treating automatic rotation of an AWS managed key as equivalent to customer-controlled rotation and revocation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSE-KMS with a customer managed key in AWS KMS, with automatic key rotation enabled.
Using SSE-KMS with a customer managed key lets the company define the key policy, enable automatic rotation, and disable the key to immediately block decryption. AWS managed keys cannot be disabled or rotated on a company-defined schedule, and SSE-S3 keys are fully managed by AWS, so neither provides the required control or revocation capability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Client-side encryption with a data key stored in the application configuration file.
Why it's wrong here
Storing a data key in an application configuration file exposes the key material and provides no centralized revocation mechanism. Although client-side encryption gives the company control, disabling access requires rotating the stored key and redeploying, which is not an immediate, centralized revocation like disabling a KMS key.
- ✗
SSE-S3 with bucket versioning enabled and S3 Object Lock in compliance mode.
Why it's wrong here
SSE-S3 uses AWS-owned keys, so the company cannot control rotation or disable a key to revoke access. Object Lock and versioning protect against deletion or overwrite but do not give the company a customer managed key that can be disabled to cut off decryption immediately.
- ✓
SSE-KMS with a customer managed key in AWS KMS, with automatic key rotation enabled.
Why this is correct
A customer managed key in AWS KMS gives the company control over the key policy, rotation settings, and key state. Enabling automatic rotation rotates the backing key material annually while retaining the same key ID, and disabling the key immediately prevents new decrypt operations, satisfying both the rotation and revocation requirements.
- ✗
SSE-KMS with an AWS managed key (aws/s3) and automatic annual rotation enabled.
Why it's wrong here
AWS managed keys are rotated by AWS on a fixed schedule that the customer cannot change, and the customer cannot disable or delete an AWS managed key to revoke access. This fails the requirement for company-controlled rotation and immediate revocation.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.